Search

Find merged stories by title or summary.

DFIR
Emerging1 src

InfoSec News Nuggets – 09/04/2026

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks SonicWall is urging customers running its SMA1000 series secure remote access appliances to patch two zero-day vulnerabilities that have already been exploited in the wild, both discovered internally by the vendor. CVE-2026-83548 (CVSS 10. 0) is a pre-authentication SSRF flaw in the Appliance Work Place interface that lets an unauthenticated attacker reach sensitive internal functionality, while CVE-2026-83549 (CVSS 7. 8) is an OS command injection flaw in the Appliance Management Console — Rapid7 notes the two can be chained together for fully unauthenticated remote code execution.

·AboutDFIR
Read →
Vulnerabilities & Patches
Emerging1 src

Attackers exploit zero-days in consistently besieged SonicWall product

SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months. The vendor disclosed and released patches for the defects — CVE-2026-83548 and CVE-2026-83549 — and noted both were already actively exploited in the wild in a security advisory Tuesday. The Cybersecurity and Infrastructure Security Agency added the defects to its known exploited vulnerabilities (KEV) catalog Wednesday. SonicWall customers have confronted a barrage of actively exploited vulnerabilities in SonicWall devices for years. Attackers have consistently exploited newly discovered zero-days and years-old defects in the vendor’s products to break into victim environments.

·CyberScoop
Read →
Vulnerabilities & Patches
Emerging1 src

SonicWall Vulnerabilities Exploited in the Wild

CVE-2026-83548: A critical, unauthenticated server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. It allows attackers to reach sensitive internal functionality through an unintended access path. CVE-2026-83549: A high-severity OS command injection vulnerability in the Appliance Management Console (AMC). It can allow arbitrary operating-system command execution. These two vulnerabilities can be chained together to achieve unauthenticated remote code execution, allowing attackers to access sensitive functionality and perform unauthorized operations. CVE CVE-2026-83548 CVE-2026-83549 Affected Products SMA1000 Models – 6210, 7210, 8200v running the following versions:

·Malware.news
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

SonicWall reports two major security holes under active exploit

SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authentication, highly troubling. In its security alert , SonicWall described the first hole, tracked as CVE-2026-83548 and rated 10 (critical) in severity, as a “Pre-authentication SSRF vulnerability [that] exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.”

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances. CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3. 1 base score of 10. 0 and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path. CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its own, exploitation requires an authenticated administrator and specific system conditions.

·Rapid7 Blog
Read →
Vulnerabilities & Patches
Emerging1 src

SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs

SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. • CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF vulnerability in the Appliance Work Place interface. A remote unauthenticated attacker could exploit it to access sensitive functionality and perform unauthorized operations. • CVE-2026-83549 (CVSS 7.8) is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC). A remote attacker authenticated as an administrator could exploit it under specific conditions to execute arbitrary commands and achieve remote code execution.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

SonicWall security advisory (AV26-872)

Serial Number: AV26-872 Date: September 2, 2026 As of September 1, 2026, SonicWall is affected by a vulnerability in the following product: • SMA1000 - 6210, 7210, 8200v • 12.4.3-03453 (platform-hotfix) and older versions • 12.5.0-02835 (platform-hotfix) and older versions SonicWall indicates that CVE-2026-83548, CVE-2026-83549 are being exploited. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • Security Advisory • SonicWall Security Advisories SonicWall security advisory (AV26-872) - Canadian Centre for Cyber Security

·Malware.news
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

SonicWall SMA 1000 appliances under attack via zero-day flaws

Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built for scale. They are used regularly by medium to large enterprises, government agencies, and managed security service providers. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw in the Appliance Work Place interface, and allows … More → The post SonicWall SMA 1000 appliances under attack via zero-day flaws appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-83548 - SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

·CISA KEV
Read →

You've reached the end of current stories for this search.